arXiv:2605.03034cs.AIcs.CR2026-05被引 3

用工具约束大模型,实现安全防御中的稳定自治决策。

Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense

  • 大模型通过确定性工具和有限动作集进行决策,确保系统可控性。
  • 在真实攻击图上,防御方收益提升59%,且40次实验无波动。
  • 适合关注自动化安全防御的工程师与研究者,尤其重视系统稳定性者。

在对抗性压力下进行高风险决策的智能体需要形式化保证,现有方法无法提供。针对安全运营中心(SOC)需在对抗压力下配置终端检测与响应(EDR)策略的实际需求,我们提出一种工具中介架构:大语言模型(LLM)代理使用确定性工具(斯塔克尔伯格最优响应、贝叶斯观测更新、攻击图原语),并从有限动作目录中选择,动作选择受制于工具输出接口。一个在Lean 4中机器验证的复合李雅普诺夫函数,证明了系统在非对称传感器数据下的可控制性、可观测性,以及在智能对抗干扰下的输入到状态稳定性(ISS)鲁棒性,并有两个推论将证书扩展至目录中任意控制器或对手。在282个真实企业攻击图上,该结论成立且有余量。在配对的攻防遥测数据中,工具中介的Claude Sonnet 4控制器相比确定性贪婪基线,使攻击者预期收益降低59%,40次运行中无方差。另一控制器Claude Haiku 4.5虽收敛至次优博弈值,但始终处于动作目录边界内,表明架构稳定性不依赖控制器能力。大模型的非确定性促进策略探索,而工具中介架构保障系统稳定。

原文摘要 · Abstract (English)

Agentic systems involved in high-stake decision-making under adversarial pressure need formal guarantees not offered by existing approaches. Motivated by the operational needs of security operations centers (SOCs) that must configure endpoint detection and response (EDR) policies under adversarial pressure, we present a tool-mediated architecture: LLM agents use deterministic tools (Stackelberg best-response, Bayesian observer updates, attack-graph primitives) and select from finite action catalogs enforced at the tool-output interface. A composite Lyapunov function machine-checked in Lean 4 with zero sorry certifies controllability, observability from asymmetric sensor data, and Input-to-State Stability (ISS) robustness under intelligent adversarial disturbance, with two corollaries extending the certificate to any controller or adversary from the catalogs. On 282 real enterprise attack graphs, the claims hold with margin. On paired offensive/defensive telemetry, a tool-mediated Claude Sonnet 4 controller reduces the attacker's expected payoff (game value) by 59% relative to a deterministic greedy baseline, with zero variance across 40 runs at four temperatures. A Claude Haiku 4.5 controller converges to suboptimal game values but stays catalog-bounded over an additional 40 runs, demonstrating that architectural stability is not dependent on the controller capability. The LLM agent's non-determinism furthers creative exploration of strategies, while the tool-mediated architecture ensures system stability.

安全防御智能体大模型稳定性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。